Cisco Talos reported that Chinese-speaking threat actor UAT-10147 targeted vulnerable internet-facing Windows IIS and Linux servers worldwide, using publicly disclosed one-day flaws to gain access and then deploying a broad post-compromise toolkit tied to SEO fraud and data theft. Talos said the group used AI-assisted workflows to automate reconnaissance, exploit validation, payload deployment, persistence, and operational documentation, and maintained infrastructure suggesting significant scale, including a target list of roughly 170,000 URLs. On compromised Windows systems, the actor used batch scripts, scheduled tasks, rogue user creation, EfsPotato, and Defender exclusions; on Linux, it relied on web shells and local privilege-escalation exploits to obtain root access.
A central payload in the campaign was SPECTRE, a custom cross-platform backdoor for Windows and Linux that supports HTTP-based command and control, anti-analysis, process injection, credential access, and on Windows a BYOVD technique to reduce EDR visibility by unlinking kernel callbacks. On Linux, SPECTRE deployed a rootkit called Specter, disguised as acpi_pad.ko and persisted through a fraudulent systemd service to hide processes and modules and elevate privileges. Talos also observed Noodle RAT, QuasarRAT, Gh0stCringe, Meterpreter, and web shells in the same operations; prior research has linked Noodle RAT variants to multiple Chinese-speaking espionage and financially motivated clusters, including Linux samples that copy themselves to /tmp/CCCCCCCC, decrypt configuration with RC4 using the hardcoded key r0st@#$, and connect to attacker-controlled C2 servers.

Pull IOCs and campaign context straight into your stack.
16 events from the most recent confirmed update back to the earliest known activity.
Talos reported that the Linux variant of SPECTRE deployed a kernel rootkit named Specter disguised as acpi_pad.ko and persisted it with a fraudulent hardware-monitor.service configured to load before security tooling during boot.
Talos said the Windows variant of SPECTRE downloaded vulnerable drivers RTCore64.sys and DBUtil_2_3.sys and used kernel callback unlinking to suppress EDR visibility for the remainder of the session.
Cisco Talos described UAT-10147's custom cross-platform SPECTRE backdoor and its Linux Specter rootkit, outlining capabilities for anti-analysis, HTTP C2, credential theft, persistence, privilege escalation, and defense evasion.
Cisco Talos reported that UAT-10147 had been deploying the previously unreported cross-platform SPECTRE backdoor since at least April 2026. The implant was described as a C-based HTTPS backdoor supporting up to 45 commands across Windows and Linux.
Talos said that after gaining root on Linux systems, UAT-10147 deployed implants including NoodleRAT, SPECTRE, and Meterpreter that connected outbound to attacker-controlled infrastructure.
Talos reported that after initial remote code execution on Linux, UAT-10147 deployed web shells for interactive access and used local privilege-escalation exploits including CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, and CVE-2022-0847 to obtain root.
Talos observed UAT-10147 using Windows batch scripts, EfsPotato, Defender exclusions, scheduled tasks, rogue user creation, and likely BadIIS deployment to maintain access and support SEO fraud operations.
Talos found that UAT-10147 used AI-driven tooling in early 2026 to automate reconnaissance, exploit development, validation, payload deployment, persistence, and operational documentation during post-compromise operations.
Talos observed UAT-10147 using publicly disclosed one-day flaws for remote code execution, including CVE-2022-27925 in Zimbra, CVE-2021-23758 in AjaxPro, CVE-2021-29441 and CVE-2021-29442 in Nacos, and CVE-2019-18935 in Telerik UI for ASP.NET AJAX.
Cisco Talos reported that in early 2026, the Chinese-speaking financially motivated group UAT-10147 targeted vulnerable Windows and Linux internet-facing web servers across multiple sectors and countries.
Researchers identified two Win.NOODLERAT clusters, Type 0x03A2 and Type 0x132A, based on the command ID returned after successful C2 authentication and documented their differing command structures and capabilities.
In its August 20, 2026 technical analysis, Cisco Talos said development artifacts in UAT-10147 tooling referenced the pseudonym “xshen”/“x神”. Talos also reported indicators of Vietnam-focused targeting, including a QuasarRAT campaign string and SEO tooling aimed at the Cốc Cốc browser ecosystem.
Talos discovered the activity after a compromised machine contacted 139.180.197[.]150 and found an open directory on that infrastructure containing a target list of about 170,000 URLs split into 17 files.
Trend Micro attributed the Win.NOODLERAT Type 0x132A cluster only to Calypso APT and noted that this version included the full feature set, including self-deletion, indicating it was likely exclusive to that actor.
Trend Micro said the Win.NOODLERAT Type 0x03A2 cluster was used by Iron Tiger and other unknown espionage clusters, suggesting this variant was shared across operators.
Trend Micro reported that the ELF-based Linux.NOODLERAT variant had been used by multiple groups, including Rocke for financially motivated activity, the Cloud Snooper campaign for espionage, and another unknown spying cluster.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 68 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
10 references tracked. Mallory keeps watching after this page renders.
blog.polyswarm.io
Open sourcereversinglabs.com
Open sourcecommunity.gurucul.com
Open sourcethehackernews.com
Open sourceblog.talosintelligence.com
Open sourceblog.talosintelligence.com
Open sourcecyberveille.ch
Open sourcetrendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.